81ace4c307c53dcb5aa5e1d7a971d373a734c747408be3a9158bb00b5b11f8a2

Classification: Malicious

81ace4c307c53dcb5aa5e1d7a971d373a734c747408be3a9158bb00b5b11f8a2 is a malicious file sample. Linked to Agent Tesla malware. Detected by 24 antivirus engines.

Detection summary

  • 24 antivirus detections
  • 0 IDS alerts
  • 4 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: AGENT TESLA (S0331)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-03-25 07:45:03 2026-09-02 17:45:05 malicious-activity
AgentTesla MalwareBazaar Abuse.ch 2024-03-25 07:27:37 2024-03-25 07:27:37 malicious-activity S0331 Agent Tesla

Tags

evasive

Sample information

Filenames
81ace4c307c53dcb5aa5e1d7a971d373a734c747408be3a9158bb00b5b11f8a2, SecuriteInfo.com.Win32.PWSX-gen.23449.29887
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
727040 bytes
MD5
7806be4f71ce1b0fc27c40974ecb5041
SHA-1
bb38809901742d73eccbce01f4576aa6301d35fb
SHA-256
81ace4c307c53dcb5aa5e1d7a971d373a734c747408be3a9158bb00b5b11f8a2
First indexed
2024-03-25 07:27:53
Last updated
2026-09-02 17:45:06

Antivirus detections

EngineDetection
APEXMalicious
AVGPWSX-gen [Trj]
AvastPWSX-gen [Trj]
BkavW32.AIDetectMalware.CS
CrowdStrikewin/malicious_confidence_100% (W)
DeepInstinctMALICIOUS
ESET-NOD32a variant of MSIL/GenKryptik.GVKJ
Elasticmalicious (high confidence)
FortinetMSIL/GenKryptik.PWSX!tr
GoogleDetected
KasperskyUDS:Trojan-PSW.MSIL.Agensla.gen
LionicTrojan.Win32.AgentTesla.4!c
MalwarebytesMachineLearning/Anomalous.100%
MaxSecureTrojan.Malware.300983.susgen
MicrosoftTrojan:Win32/Wacatac.B!ml
RisingMalware.Obfus/[email protected] (RDM.MSIL2:G9gjdYb+T49PD2FYfogURg)
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.bc
SophosTroj/Krypt-ABH
SymantecScr.Malcode!gdn33
VBA32TrojanLoader.MSIL.DaVinci.Heur
VirITTrojan.Win32.MSIL_Heur.A
ZoneAlarmUDS:Trojan-PSW.MSIL.Agensla.gen

Process list

NameCommand line
SecuriteInfo.com.Win32.PWSX-gen.23449.29887.exe
SecuriteInfo.com.Win32.PWSX-gen.23449.29887.exe
SecuriteInfo.com.Win32.PWSX-gen.23449.29887.exe
SecuriteInfo.com.Win32.PWSX-gen.23449.29887.exe